YJSoft / xe-core-old

PHP Open Source CMS
http://www.xpressengine.com
Other
0 stars 0 forks source link

CVE-2022-0144 (High) detected in cudatextlinter.JavaScript_using_jshint #88

Open mend-bolt-for-github[bot] opened 7 months ago

mend-bolt-for-github[bot] commented 7 months ago

CVE-2022-0144 - High Severity Vulnerability

Vulnerable Library - cudatextlinter.JavaScript_using_jshint

Cross-platform text and code editor

Library home page: https://sourceforge.net/projects/cudatext/

Found in HEAD commit: 721f00c7479af73f0a73be46c2bc6853e1da863b

Found in base branch: master

Vulnerable Source Files (2)

/node_modules/shelljs/src/exec.js /node_modules/shelljs/src/exec.js

Vulnerability Details

shelljs is vulnerable to Improper Privilege Management

Publish Date: 2022-01-11

URL: CVE-2022-0144

CVSS 3 Score Details (7.1)

Base Score Metrics: - Exploitability Metrics: - Attack Vector: Local - Attack Complexity: Low - Privileges Required: Low - User Interaction: None - Scope: Unchanged - Impact Metrics: - Confidentiality Impact: High - Integrity Impact: None - Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2022-01-11

Fix Resolution: shelljs - 0.8.5


Step up your Open Source Security Game with Mend here